Описание
xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Clients can intercept D-Bus messages they should not have access to. This vulnerability is fixed in 0.1.7.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 0.1.7-1 |
| esm-infra/focal | released | 0.1.2-1ubuntu0.1~esm1 |
| jammy | released | 0.1.3-1ubuntu0.1 |
| noble | released | 0.1.5-1ubuntu0.2 |
| questing | released | 0.1.6-1ubuntu0.1 |
| resolute | not-affected | 0.1.7-1 |
| upstream | released | 0.1.7-1 |
Показывать по
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Clients can intercept D-Bus messages they should not have access to. This vulnerability is fixed in 0.1.7.
xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Clients can intercept D-Bus messages they should not have access to. This vulnerability is fixed in 0.1.7.
xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0. ...
EPSS
5.5 Medium
CVSS3